Question

Why is identity recovery such a sensitive process, and how should an organization go about validating...

Why is identity recovery such a sensitive process, and how should an organization go about validating identity?

0 0
Add a comment Improve this question Transcribed image text
Answer #1

Identity verification is the process of verifying that a person’s digital identity matches their physical identity when conducting business online. It is a vital component to transaction ecosystems such as eCommerce companies, financial institutions, online gaming, and even social media.

An example of this is the prompt to verify your identity when signing up for a new service, applying for a credit card, or even resetting your password.

The verification methods have their own strengths and weaknesses. When selecting a method, consider the level of access being granted, the type of data being accessed, and the action being performed.

Access to sensitive data, such as personally identifiable information, health or financial data requires the highest degree of verification. The same can be said of users who have privileged access, or the ability to cause significant damage within a network. Users with limited system access, who don’t handle sensitive data, can use a simpler verification method.

The verification method needs to be responsive to the action performed. When a user logs onto their corporate computer from within the company network, there are low risk signals – company computer, company network. When that user tries to reset their password from an unknown device outside of the network, there are high risk signals which require more secure verification.

For optimal security, you will have to go beyond a single point of vulnerability. A multi-factor method, a combination of the verification categories, reduces the likelihood of comprise. Multi-factor authentication is widely used for online banking, and can also be enabled for many online accounts, including Google, Facebook, Microsoft, Apple. Companies are also looking to multi-factor authentication to reduce vulnerabilities associated with passwords, and security questions. Since NIST no longer endorses security questions for protecting accounts, organizations are implementing alternate solutions when verifying users through the helpdesk, or during self-service password resets.

Add a comment
Know the answer?
Add Answer to:
Why is identity recovery such a sensitive process, and how should an organization go about validating...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT